Privacy Policy
Effective date: 28 August 2026
This policy describes how the private, single-user SWP Hermes Backup utility handles Google user data.
Data accessed
The utility requests only https://www.googleapis.com/auth/drive.file. It accesses the IDs, names, sizes, checksums, parent relationships, timestamps, and trash state of Google Drive folders and files created through this OAuth application. It does not request Gmail, Calendar, Contacts, Docs, Sheets, or broad access to unrelated Drive files.
How data is used
Google Drive data is used only to create a dedicated backup folder, upload encrypted Hermes backup archives and checksum files, verify successful uploads, calculate safe retention, and remove eligible app-created backups when the account owner has explicitly enabled retention deletion.
Storage and security
OAuth client credentials and tokens are stored only in the private Hermes environment on the owner-controlled VPS. Hermes backup archives are encrypted before upload using a public recovery key. The private recovery key is kept outside the VPS. This public website stores no OAuth tokens, backup contents, or Google Drive file data and uses no analytics, advertising, cookies, or third-party scripts.
Sharing and disclosure
Google user data is not sold, rented, shared with advertisers, or transferred to third parties. It is used solely to provide the backup functionality requested by the account owner, consistent with the Google API Services User Data Policy and its Limited Use requirements.
Retention and deletion
Encrypted backups remain in the dedicated Google Drive account until removed by the account owner or by an explicitly approved retention policy. The utility is restricted to files it created inside its exact backup folder. Revoking the application's access in the Google Account security settings stops future access; existing Drive files can then be deleted directly by the account owner.
Contact
Questions may be sent to the user-support email displayed on the Google OAuth consent screen.